Sploitus

CVE-2026-57231

No indexed exploits for CVE-2026-57231 yet

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

Affected products
Podman, Red Os, Rocky Linux
Podman Project Podman
< 5.8.4, 6.0.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.3% (24th percentile)
Weakness
CWE-668, CWE-200
NVD status
Analyzed
Published
2026-06-26
CVE-2026-57231 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-57231 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-57231 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.